CVE-2026-105793
Deferred Deferred - Pending Action

Microsoft UFO Key Injection Vulnerability

Vulnerability report for CVE-2026-105793, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO_MCP_API_KEY, adb on the host, and a reachable authorized device, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft UFO < 3.0.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Microsoft UFO before 3.0.9 has a vulnerability in the press_key tool where a free-form key_code parameter is passed to adb shell input keyevent. This allows an authenticated Mobile MCP caller to execute additional commands as the Android shell user on a connected device.

Detection Guidance

To detect this vulnerability, check the version of Microsoft UFO installed on your system. If it is below 3.0.9, the system is vulnerable. Review logs for unauthorized use of the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py.

Impact Analysis

An attacker with a valid UFO_MCP_API_KEY and access to an authorized device could execute unauthorized commands on the Android device with shell-user privileges. This does not allow root access or host OS execution.

Mitigation Strategies

Upgrade Microsoft UFO to version 3.0.9 or later immediately. Ensure the UFO_MCP_API_KEY is secured and restrict access to authorized devices only. Monitor network traffic for suspicious adb shell commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105793. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart